Ethereal-users: Re: [Ethereal-users] windows 2000 decode

Note: This archive is from the project's previous web site, ethereal.com. This list is no longer active.

From: Guy Harris <guy@xxxxxxxxxx>
Date: Tue, 21 Jan 2003 23:37:16 -0800
On Tue, Jan 21, 2003 at 10:59:14AM -0800, Guy Harris wrote:
> It can be more accurately decoded by finding documentation for that
> packet's format and adding code to the NETLOGON dissector to dissect
> that packet based on that documentation, or perhaps by having some other
> packet analyzer decode it (if any do) and having Ethereal dissect it
> similarly.

Well, neither Microsoft Network Monitor nor Sniffer Pro seem to know
what the heck an opcode of 17 is in a NETLOGON packet, so, unless
somebody finds a sniffer that does know what it is, or finds
documentation for it, or otherwise guesses what it is, it's not going to
get dissected by Ethereal.